Quick summary
- We do not collect your email. There is no newsletter signup and no tool on this site requests an email address.
- We use privacy-respecting analytics (aggregated traffic only, no personal profiles).
- We never sell, rent, or share personal data with third parties for their marketing.
- You can request access, correction, or deletion of your data at any time.
Updated 5 August 2026: no forms, no email capture, no lead database
nhigovernance.com is a static publication with no forms, no newsletter signup, no email capture, no accounts and no server-side data handling. The interactive tools run entirely in your browser and your answers are never transmitted anywhere. There is no lead database and no CRM behind this site.
The only data processed is privacy-configured Google Analytics, which is disabled by default until you accept it in the cookie banner. Google Signals and ad personalisation are switched off. If you decline, no analytics cookies are set.
If you contact us by email, we hold that email in order to reply to it. That is the entire scope.
1. Who is the data controller
The data controller for personal information collected on nhigovernance.com is HumanAudit Inc., a Delaware C-Corp ("we", "us", "our"). Contact for privacy matters: truth@humanaudit.ai. For EU data-subject matters, the same address applies; we have appointed an internal privacy lead who can be reached at this address.
2. What information we collect
We collect only what we need. The categories are:
- Forms and submissions. This site has no forms. Nothing you enter into an interactive tool leaves your browser.
- Email engagement data. Our email platform records whether messages are delivered, opened, and which links are clicked.
- Web analytics. We use Google Analytics 4 (measurement ID
G-MT2LMPHNW9) configured to aggregate traffic (page views, referrers, approximate country, device type) only after explicit consent via the cookie banner, with Google Consent Mode v2 defaulting all storage categories to denied until you accept. Google Signals and ad-personalisation signals are disabled in our configuration, and we do not share GA data with advertising networks. See our cookie policy for specifics. - Contact correspondence. If you email us, we retain the message and its content for as long as reasonably necessary to respond and for a reasonable period thereafter.
- Server logs. Our hosting provider retains standard server-access logs (IP address, user agent, timestamp, URL requested) for a short retention window, used solely for security monitoring and abuse prevention.
3. Legal basis and why we collect it
Under the EU General Data Protection Regulation (GDPR) and UK GDPR, we rely on the following legal bases:
- Consent (Art. 6(1)(a)), for newsletter subscription, tool email-delivery, and non-essential cookies. You may withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)), for essential site operation, security monitoring, and aggregated analytics. We have balanced our interest in operating a secure, useful website against your privacy interests and concluded the processing is proportionate.
- Contractual necessity (Art. 6(1)(b)), where relevant to any paid service you engage (note: no paid services are sold on this site; paid products exist on sister sites under separate privacy notices).
- Legal obligation (Art. 6(1)(c)), where we are required to retain or disclose data under applicable law.
4. How we use your information
We use the information we collect to:
- Deliver tool results, remediation guides, or assessment reports you have explicitly requested.
- Respond to messages you send us.
- Measure aggregated site traffic and improve content.
- Monitor for abuse and ensure the security of the site.
- Comply with applicable law.
We do not use your personal data to build advertising profiles, to retarget you across the web, or to share with third-party marketers. We do not use your data to train machine-learning models.
5. Who we share data with
We share data only with service providers
- Our web host, for serving these pages.
- Our hosting and content-delivery provider, for serving the site.
- Our analytics provider, configured to process only aggregated data.
- Professional advisors (accountants, lawyers) where required.
- Law enforcement or regulators where legally compelled.
We hold no personal data to share. We do not sell, rent or transfer anything to any third party for any purpose.
6. International data transfers
HumanAudit Inc. is based in the United States. Certain service providers may process data in the United States or other jurisdictions outside the EEA or UK. Where required, we rely on appropriate transfer mechanisms including Standard Contractual Clauses (SCCs) and supplementary measures in line with the European Commission's decisions and EDPB guidance.
7. How long we keep data
- Contact correspondence: retained for a reasonable period to allow for follow-up and records, then deleted.
- Analytics data: aggregated data retained in line with the analytics tool's settings; no individual profiles retained.
- Server logs: short retention window (weeks, not years) unless required for a security investigation.
8. Your rights
You have the following rights in respect of your personal data. Many are enshrined in the GDPR / UK GDPR, and similar rights are provided under the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, and other comparable laws.
- Access. Request a copy of the personal data we hold about you.
- Rectification. Request correction of inaccurate or incomplete data.
- Erasure. Request deletion of your data, subject to limited legal exceptions.
- Restriction. Request restriction of processing in certain circumstances.
- Portability. Request your data in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interests.
- Withdrawal of consent. Withdraw consent at any time where consent is the legal basis.
- Complaint. Lodge a complaint with your local data protection authority. In the EU, a list is available from the European Data Protection Board. In the UK, the ICO.
To exercise any of these rights, email truth@humanaudit.ai. We respond to verified requests within 30 days (or the period required by applicable law).
9. Children's data
This site is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us and we will delete it.
10. Security
We apply commercially reasonable technical and organisational measures to protect personal data from unauthorised access, alteration, disclosure, or destruction. This includes encryption in transit (TLS), restricted administrative access, and vendor selection based on security posture. No system is perfectly secure; we will notify affected users and relevant authorities in the event of a personal-data breach as required by law.
11. Changes to this policy
We may update this policy from time to time. The "effective" date at the top reflects the current version.
12. Contact
For any privacy question or to exercise your rights: truth@humanaudit.ai. For general enquiries unrelated to privacy: hello@nhigovernance.com.